Live data from Hacker News

The Equifax Breach Exposes America's Identity Crisis

wired.com

121–130 of 132 posts

Re: The Equifax Breach Exposes America's Identity Crisis

#121
post #38

Something non-US folks don't always get about the US -- in a lot of ways, the US is more analogous to the EU than it is to any one country of Europe. That is to say, the US Government is the national entity, but quite a lot of power is still held in the states. There is a 200+ year wariness of federal power here. One of the ways this manifests itself is that identity is established and maintained largely by the state…

> National IDs are a nonstarter politically in the US. One side thinks it is undue encroachment on local rights, and the other side thinks requiring ID disenfranchises the poor and undocumented. That's the tl;dr version of course -- reality is more nuanced. As a non-American, this doesn't really make much sense to me. There's already a national ID, the Social Security card. It's just a really really terrible form of…

We're Americans, we don't have to make sense and float in oceans of hypocrisy.

"You can always count on Americans to do the right thing - after they've tried everything else." - Winston Churchill

Re: The Equifax Breach Exposes America's Identity Crisis

#122
post #38

Something non-US folks don't always get about the US -- in a lot of ways, the US is more analogous to the EU than it is to any one country of Europe. That is to say, the US Government is the national entity, but quite a lot of power is still held in the states. There is a 200+ year wariness of federal power here. One of the ways this manifests itself is that identity is established and maintained largely by the state…

An Example: https://www.aclu.org/other/5-problems-national-id-cards

And some arguments are laughable.

> What happens when an ID card is stolen? What proof is used to decide who gets a card?

Mine has a picture on it. If this argument is true, then why does any country issue passports, drive licenses, etc...? Why do security enforce agencies have identifications? They are not perfect, but they work.

> An ID card system will lead to a slippery slope of surveillance and monitoring of citizens.

The "slippery slope" theory is just the straw-man fallacy on disguise.

> A national ID would require a governmental database of every person in the U.S. containing continually updated identifying information. It would likely contain many errors, any one of which could render someone unemployable and possibly much worse until they get their ""file"" straightened out.

This is the definition of what Equifax is. But it gets worse as people gets into no flight lists because they share the same name than a person of interest. The lack of an ID card just magnifies the problem, it doesn't makes it disappear. (http://www.nbcsandiego.com/news/local/Same-Name-Mistaken-Ide...)

> How long before office buildings, doctors' offices, gas stations, highway tolls, subways and buses incorporate the ID card into their security or payment systems for greater efficiency?

This information is already available for credit card companies. Is that better? And in Europe we have ID cards, and they are not used for any of that things. Except maybe the doctor office, as your life depends on having reliable data and it is part of your health care rights provided by the government.

> A national ID card would have the same effect on a massive scale, as Latinos, Asians, Caribbeans and other minorities became subject to ceaseless status and identity checks from police, banks, merchants and others.

This says more about USA culture than about id cards. Also, it already happens (e.g. the POTUS pardon).

Re: The Equifax Breach Exposes America's Identity Crisis

#123
post #86

Earlier quoted context omitted.

I would suggest that getting credit faster and more easily is not a benefit for consumers but a benefit to business also.

> I would suggest that getting credit faster and more easily is not a benefit for consumers but a benefit to business also Access to credit reduces poverty, internationally [1] and domestically [2]. It is also critical to letting poor and middle class individuals start small businesses [3]. Consumers and businesses benefit from financial systems that efficiently allocate credit. That's why both consumers and business…

My prior expectation of almost any of the aspiring business-owners that you describe, is that they do not have the knowledge necessary to successfully run their business.

Re: The Equifax Breach Exposes America's Identity Crisis

#124
post #14
post #9

Earlier quoted context omitted.

Anything collected will eventually leak. The issue is that companies shouldn't be collecting ANYTHING , and what they do collect should get purged ASAP. The problem is that every company got addicted to collecting information and nobody made them pay the price for doing so.

There are legitimate use cases where collecting and storing (in some manner at least) is necessary. You cannot just stop companies from collecting information, and furthermore stop them from storing any of it. Thats just naive.

Really? I don't buy it.

A corporation needs my name, address, and probably email to do business with me. They need a credit card number when I purchase something and never else.

That's IT.

My phone number is not necessary (and everybody using it for 2 factor just makes everything less secure). What I buy is not necessary to record past fulfillment. When I buy is not necessary to record. Where I am is not necessary to record. etc. If a company stores this stuff and it gets leaked, they should be liable.

A couple of egregiously expensive fines will stop companies from collecting this information quite nicely, thank you.

Re: The Equifax Breach Exposes America's Identity Crisis

#125
post #71

Earlier quoted context omitted.

Why should the government have it at all? Just let private citizens manage their own private key.

And what happens when people inevitably lose their private key? How will they regain access to their SSN?

They would probably have to through a similar procedure as they do to get a replacement social security card. That is, they would have to present at least a drivers license and US passport at one of the local social security administration offices.

At that point, they can regenerate the key-pair and have the SSA official sign the public key and keep that on file.

Now, presumably, it is possible to forge both documents, but I would think that the government could check their records (federal and state) to verify the authenticity of the provided documentation.

Re: The Equifax Breach Exposes America's Identity Crisis

#126

The article goes a bit off the rails at the end, with all the focus on using a changeable identifier ("And if this new identifier were easy enough to change (unlike SSNs), breaches, leaks, and other unintended exposures would be less consequential.") There's no reason not to keep SSN as an identifier. Just the same as I wouldn't change my name if I suffered identity theft. Instead there needs to be authentication (eg…

Couldn't we do this thorugh a system that's similar to PKI? That is, have each person generate a private-key and certificate signing request (that's signed by the appropriate government agency)?

Resetting it outside the normal certificate expiration time would require that one go to the local branch of the government office to do so (much like getting a replacement social security card or replacing a lost or stolen passport). At that point, you would have to provide proof of your identify that would be verified by the government agency.

Re: The Equifax Breach Exposes America's Identity Crisis

#127
post #80

Earlier quoted context omitted.

Use SSN for identity, but use a shared secret as authorization to use that identity. Get SSN, name, place and time of birth, and birth name of mother. In theory 1 SSN maps to 1 (name, place and time of birth + mother's name) tuple, unless you have a twin and you are both called John. (Also, identity verification should could also use biometric data.) Banks already issue PINs to users, they should issue one for regula…

SSNs of people before 2011 contain place of birth as the first five digits, with the last four digits assigned sequentially. Your method provides no additional security.

???

I simply argued that SSN is not security. It's at best identity. But it's a lousy one at that too, because it's hard to check and easy to fake. (You can fake the paper you get from the Social Security Admin easier than you can fake all the other pieces mentioned.)

SSN is just dumb because it's a direct function of the mentioned attributes plus a counter, that nobody can really check. (No one can distinguish identical twins based on their claimed SSN.)

Re: The Equifax Breach Exposes America's Identity Crisis

#128
post #74

Earlier quoted context omitted.

>Not at all. At least Finland and Sweden do have a social security number assigned at birth (or immigration). Maybe we are misunderstanding each other, the Codice Fiscale in Italy is the same, assigned at birth (or immigration). The difference is that it is not on the ID card (as it is - say - in Finland or Sweden or Denmark or Spain), but on a separate card. It is a "generic" identifying number with all public admin…

> Of course each country will have its own uses (or non uses) for the thing, that is generically (EU) called TIN: Exactly. In Finland (as in the US obviously) knowing someone's ID can be used to cause damage to the person. You can do some business in the name of the person, because it is generally but falsely assumed that knowing the number is an authentication method. In Germany, because the tax number is only used…

>I know that in Italy the tax number is used quite a lot. I could not buy a rechargable smart card for public transport, because I did not have the tax number. And when just for fun at a train ticket machine I tapped that I would like a receipt, it asked me for my tax number. Whether the number is used as an authentication method and could be misused in that context I have no idea.

No, the number is just a number, and as said it is not secret and can be generated (though with not a 100% guarantee of it being valid because of "total" homonimy).

It is only an ID number, whilst the card is (can be) a form of online ID (but only on a few specific government sites) and the said fun fact as proof of age on vending machines.

In any case it is never a password, so having it public it is not an issue, at the most you could have typed my (or someone else's) Codice Fiscale on the ticket machine, but you couldn't have used it for (if appliable) tax deduction on your name.

Re: The Equifax Breach Exposes America's Identity Crisis

#129
post #128

Earlier quoted context omitted.

> Of course each country will have its own uses (or non uses) for the thing, that is generically (EU) called TIN: Exactly. In Finland (as in the US obviously) knowing someone's ID can be used to cause damage to the person. You can do some business in the name of the person, because it is generally but falsely assumed that knowing the number is an authentication method. In Germany, because the tax number is only used…

>I know that in Italy the tax number is used quite a lot. I could not buy a rechargable smart card for public transport, because I did not have the tax number. And when just for fun at a train ticket machine I tapped that I would like a receipt, it asked me for my tax number. Whether the number is used as an authentication method and could be misused in that context I have no idea. No, the number is just a number, an…

> No, the number is just a number, and as said it is not secret and can be generated (though with not a 100% guarantee of it being valid because of "total" homonimy).

True. I had already forgotten that. Created mine a couple of years ago using some unofficial online service. Maybe I still have it on some disk... Of course I cannot be 100% sure that it is correct. I understand I could order mine officially without ever having lived in Italy. Never bothered about that, I don't have that much contact to Italy.

Re: The Equifax Breach Exposes America's Identity Crisis

#130

Earlier quoted context omitted.

The private university I went to used to issue student emails that were first three letters of last name followed by last four digits of social security number. It always seemed odd to me. Years later, they've switched and we don't have that problem any more. Companies can generate a unique identifier without using SSN. Of course, the main problem is that they can't do authentication based on that identifier. So why…

SSN is the only reliable way to disambiguate duplicate names. Differentiating all the John Smiths by mailing address is too intractable, especially when you have JS Jr. and JS III living together. It is used to construct a primary key for the database.

Except that's not always been the case, either. SSNs have always been a terrible way to disambiguate people. There are weird, crazy edge cases in SSN history. Cases exactly such as JS Jr getting the same SSN as JS III in a podunk town because the local SSA administrator was feeling lazy that day and JS III was already deceased. The federal SSA website claims that that never happened, but if you have a big enough database (say, Equifax) you can spot all kinds of simple dumb human errors like that. For many, many years the SSA left local administrators in charge: the first 5 digits and the weird way they are hyphenated were local district numbers. For people born before 2011 (!), when the new randomization scheme was switched to, there is a 90% chance you can guess their first five numbers if you know their birth date and birth city (which is why it is so ridiculous that PII rules to keep SSNs safe ever considered it fine to show only the last four, those are only meaningful digits for still the majority of SSNs in the wild).

SSNs were never designed for what the credit bureaus and banks and insurance companies (and everybody else) use them for, and there are too many cracks and failure cases. Companies need to admit their failures and come up with a real solution; but companies have so much sunk cost in SSN-keyed databases they aren't likely to ever actually do that. (Maybe this Equifax breach pushes more companies to try. Cynicism says companies remain cheap and invested in their sunk costs.)

Post reply on HN